Subject: CVS commit: pkgsrc/www/py-django
From: Adam Ciarcinski
Date: 2019-06-03 14:33:00
Message id: 20190603123300.B4417FBF4@cvs.NetBSD.org

Log Message:
py-django: updated to 1.11.21

Django 1.11.21 release notes

CVE-2019-12308: AdminURLFieldWidget XSS

The clickable “Current URL” link generated by AdminURLFieldWidget displayed \ 
the provided value without validating it as a safe URL. Thus, an unvalidated \ 
value stored in the database, or a value provided as a URL query parameter \ 
payload, could result in an clickable JavaScript link.

AdminURLFieldWidget now validates the provided value using URLValidator before \ 
displaying the clickable link. You may customise the validator by passing a \ 
validator_class kwarg to AdminURLFieldWidget.__init__(), e.g. when using \ 
formfield_overrides.

Files:
RevisionActionfile
1.106modifypkgsrc/www/py-django/Makefile
1.85modifypkgsrc/www/py-django/distinfo